FR
live

SAP patches OVERPASS and S4GET, two pre-auth flaws that run code on the SAP kernel

On September 9, 2026, SAP shipped fixes for four critical flaws, including CVE-2026-44756 (CVSS 10.0), a memory-corruption bug in Extended Passport processing that yields unauthenticated remote code execution across three protocols at once. Basis teams should patch the SAP kernel first, ahead of any network segmentation effort.

A row of border-control ink stamps, one of them raised and dipped in a single amber ink pad.

September 9, 2026. SAP shipped its monthly security update and fixed four critical flaws, two of which share a dangerous property: they are reachable without authentication, remotely, and over ports you cannot close without breaking the business itself. The most severe, CVE-2026-44756 — nicknamed OVERPASS — scores a CVSS 10.0. Discovered by Onapsis, it allows arbitrary operating-system commands on the SAP host with administrative privileges. Why it matters: a pre-auth RCE in the SAP kernel is total compromise of business data, not a peripheral incident.

OVERPASS: memory corruption inside the Extended Passport

CVE-2026-44756 lives in the SAP kernel code that processes the Extended Passport, or EPP. The EPP is a metadata structure that accompanies calls between the layers of an SAP system — an internal identity stamp that travels with requests. The flaw is a memory corruption: a missing boundary validation during deserialization of EPP data leads to a memory-safety violation when the code processes externally supplied length fields.

In practice, an unauthenticated attacker sends a crafted network request carrying a malformed EPP header. The result is not a simple crash: the defect allows taking control of the receiving process and, from there, running operating-system commands on the host with SAP administrative privileges. Onapsis CTO JP Perez-Etchegoyen put the scope plainly: “A specially-crafted request sent to an affected system can be abused to take control of the receiving process and, from there, run operating system commands on the host.”

The severity comes from the reach of the shared code. EPP processing is kernel code used by more than one protocol, so the flaw is reachable from the internet-facing web layer, from the GUI layer every end user connects to, and from the RFC layer that links SAP systems to each other. Three protocols, three attack paths, none of them requiring credentials — which, in his words, means “no single network control can fully mitigate risk.”

What an OVERPASS exploitation is worth

A successful OVERPASS exploit opens access that goes far beyond the compromised machine. An attacker can read the SAP secure store to recover database credentials, password hashes and all hosted business data; read the live session data of logged-in users; extract stored credentials to move laterally into every other SAP system; and modify application data, system configuration and the SAP binaries themselves.

This is the scenario every CISO of an S/4HANA shop dreads: not an isolated incident, but the loss of the trust root that carries billing, payroll and production. When the kernel holding the database secrets is compromised, subsequent application patches no longer suffice — you must rebuild trust, and that is measured in weeks.

S4GET: the flaw you cannot firewall away

The second critical, CVE-2026-58240 (scored CVSS 9.8), is a missing authentication check in the SAP NetWeaver Message Server. Onapsis, which also discovered it, named it S4GET. It is a logic flaw, not a misconfiguration, present in the 9.x kernel lines — the ones running S/4HANA, S/4HANA Cloud Private Edition and potentially other ABAP-based products.

What makes S4GET uniquely dangerous is its reachability. According to researcher Pablo “Partu” Agustin Artuso, the flaw is triggered through the same public port every SAP GUI client connects to — the one you cannot close without blocking end-user logon. Exploitation requires “no credentials, no certificate, and no pre-existing misconfiguration.” A successful attack yields full remote code execution as sidadm, the OS-level user that runs SAP, on every application server in the cluster.

The sentence to remember: “it cannot be firewalled away without breaking the end-user logon.” For a Basis team that is the worst case — the classic network countermeasure is off the table, and the only remaining barrier is the patch itself.

Two more criticals in the same bundle

The September 9, 2026 release contains two further critical flaws, less publicized but just as real:

  • CVE-2026-76969 (CVSS 9.4) — a credential disclosure in multi-tenant applications using the SAP Cloud Application Programming Model (CAP), letting an unauthenticated attacker obtain sensitive credentials via crafted requests, then replace or delete tenant data;
  • CVE-2026-66768 (CVSS 9.0) — an improper access control in SAP GUI for Java that allows arbitrary command execution on the underlying host.

The overall picture is consistent: SAP is concentrating these fixes on the kernel layer and the interface components the enterprise exposes by nature — the Message Server, CAP, the GUI. That is not a calendar coincidence; it reflects an attack surface where the network boundary has already been bypassed by design.

What Basis teams should do

The priority is clear, and it is not network segmentation — it is the kernel patch. OVERPASS is pre-auth, multi-protocol and reachable from the web layer; S4GET is reachable from the port every GUI client uses. No firewall rule protects against either one.

The recommended order of action:

  • Inventory exposed systemsSAP Gateway, Fiori, Web Dispatcher servers, outward-facing RFC, and any S/4HANA host reachable from a partner network;
  • Apply today’s SAP notes on the kernel and the Message Server first, ahead of peripheral application fixes;
  • Check your kernel line — the 9.x lines (S/4HANA) are the S4GET scope, but OVERPASS hits the shared EPP-processing code beyond a single line;
  • Watch for exploitation signalsOnapsis will likely publish a full technical write-up; any in-the-wild activity will turn these CVSS scores into a KEV urgency.

The deeper lesson goes beyond SAP: when a flaw is reachable “through the port everyone uses,” perimeter defense is structurally behind. The only barrier that still holds is how fast you apply the patch.

Verdict

OVERPASS and S4GET are not business-application vulnerabilities you can mitigate while waiting for a maintenance window: they are flaws in the kernel and the Message Server, reachable without authentication through paths no firewall can close without stopping the enterprise.

If your fleet runs S/4HANA or a 9.x kernel line, apply this month’s SAP notes immediately, starting with hosts reachable from outside. Treat CVE-2026-44756 as a potential compromise of the trust root, not a routine patch: a successful exploit exposes the secure store and database credentials, which forces a rebuild of trust, not just a service restart.

If you cannot patch right away, your only margin is to physically isolate SAP hosts from every network not strictly required — knowing that, for S4GET, the GUI port must stay open, and that isolation only reduces the probability, never cancels it.

References

The cyber brief, every Tuesday

The flaws that matter and the patches to apply, in a ten-minute read.

No spam. One-click unsubscribe.
read next

On the same topic

PivotC2 RAT exploits CVE-2025-25249, a Fortinet heap overflow patched since January

Patched in January 2026, the CVE-2025-25249 heap overflow in the FortiOS cw_acd daemon has resurfaced exploited in the wild: CISA added it to the KEV catalog on September 9, 2026, after SOCRadar observed the PivotC2 RAT deployed on 178 devices. Network teams must upgrade exposed FortiOS trains before September 12, then strip out unnecessary fabric access.

← Back to the feed

Type at least two characters.

navigate open esc dismiss